Lately, I've been fully invested in working with logs, traffic analysis, and expanding my knowledge of cyberattacks. Due to the specific wartime conditions and the occurrence of cyberattacks, I've had to study more and on top of that, I've done a lot of malware analysis at work. I've gained a deeper understanding of malware behavior, system internals, and their architecture. Interestingly, several pieces of malware were specifically designed to infiltrate Iran's IT infrastructure, in fact, they were geopolitically motivated cyberattacks.
Mustang Panda, the statesponsored advanced threat group Mustang Panda is targeting Iran's governmental infrastructure through a targeted phishing campaign. This pattern aligns with the known TTPs of the Mustang Panda group.
In short, I studied quite in depth concepts such as Malware, APT, LOLBins, DLL hijacking, fileless malware, polymorphic and metamorphic malware, Remote RAT, LSASS, Sandbox, obfuscation, LNK, WMI, Thread Pool, ASR, TTP and etc. Since I didn't have access to the international internet, I used an Iranian AI platform that included all the AI tools of other platforms under a single subscription, through which I obtained the necessary information. And of course, I was also able to download (through unofficial means) a number of paid video tutorials.
I had to work online and remotely with firewalls and the ELK stack, and the security of the company's infrastructure and equipment was my responsibility. It was a very valuable experience for me.